SOC Information Security and Data Privacy Controls 2 — Questions and Answers
Question 1: Under SOC 2, which Trust Service Criteria category specifically addresses the protection of personal information collected, used, retained, and disclosed?
- Availability
- Confidentiality
- Privacy (Correct answer)
- Processing Integrity
Correct answer: Privacy
The Privacy criteria (P series) in SOC 2 specifically governs how personal information is collected, used, retained, disclosed, and disposed of in conformity with commitments and applicable regulations.
Question 2: A company stores encrypted backups offsite but the encryption keys are kept in the same location as the backups. Which control weakness does this represent?
- Inadequate backup frequency
- Failure to segregate key management from encrypted data (Correct answer)
- Lack of offsite storage policy
- Missing data classification labels
Correct answer: Failure to segregate key management from encrypted data
Storing encryption keys with the encrypted data defeats the purpose of encryption, as an attacker who gains access to the backup also gains the keys needed to decrypt it.
Question 3: Which of the following best describes a data retention policy in the context of SOC 2 Privacy criteria?
- A policy defining how long data must be stored before disposal based on legal and business requirements (Correct answer)
- A technical control preventing unauthorized data modification
- A procedure for encrypting data at rest beyond the standard retention period
- A schedule for rotating encryption keys used to protect stored data
Correct answer: A policy defining how long data must be stored before disposal based on legal and business requirements
A data retention policy defines the periods for which personal information is retained based on legal obligations, business needs, and privacy commitments before it is securely disposed of.
Question 4: During a SOC 2 examination, auditors discover that access to the HR database is granted based on job title alone, without individual review. This violates which principle?
- Least privilege (Correct answer)
- Defense in depth
- Data minimization
- Non-repudiation
Correct answer: Least privilege
Least privilege requires that access rights be granted based on individual need-to-know, not broad role assignments, to minimize the risk of unauthorized data exposure.
Question 5: A SOC 2 report user notices the report covers only the period January 1 to March 31. What is the significance of this date range?
- It indicates the service organization only operates in Q1
- It defines the period of time controls were tested and must be verified for ongoing engagements (Correct answer)
- It reflects the fiscal year of the service auditor
- It represents the maximum allowable period for a SOC 2 Type I report
Correct answer: It defines the period of time controls were tested and must be verified for ongoing engagements
The examination period in a SOC 2 Type II report specifies the duration over which controls were observed and tested, and report users must consider whether this period aligns with their own risk assessment needs.
Question 6: Which of the following is an example of a preventive control for information security?
- Reviewing audit logs for suspicious activity
- Conducting a post-incident forensic investigation
- Requiring multi-factor authentication before system access (Correct answer)
- Generating alerts when failed login attempts exceed a threshold
Correct answer: Requiring multi-factor authentication before system access
Multi-factor authentication is a preventive control because it stops unauthorized access before it occurs, as opposed to detective controls that identify issues after the fact.
Question 7: Under the AICPA's Privacy Management Framework, which principle requires that individuals be informed about what personal data is collected and how it will be used?
- Use, retention, and disposal
- Notice and communication (Correct answer)
- Access
- Monitoring and enforcement
Correct answer: Notice and communication
The Notice and Communication principle requires organizations to inform individuals about their personal data practices, including what data is collected, why, and how it is used.
Under SOC 2, which Trust Service Criteria category specifically addresses the protection of personal information collected, used, retained, and disclosed?